Privacy policy
Written to be read. Where something costs you privacy, it says so in the same size type as everything else.
Last updated 8 August 2026
The short version
Your mail lives with your mail provider and on your devices. Tiho is the software you read it with. Two of our services touch your mail at all, and both are described below in full: the one that tells you a message arrived, and the one that fetches images so senders can't watch you.
What stays on your device
Messages, attachments, search index, drafts, and the credentials for any mailbox you connect. Credentials are held in the system keychain — the same place your other applications keep passwords — and never in ordinary application settings.
Mail is stored so it can be read without a network. Deleting the account from the app erases the stored mail and the stored credentials from that device.
Notifications, and what they cost
This is the part most policies bury, so it goes first.
To tell you the moment a message arrives, our server keeps a live connection to your mailbox. That requires it to hold access to the mailbox — a token or a password, encrypted at rest.
What it does with that access:
- It observes that something arrived in the folder, and reads that one message’s sender and subject, and the first few hundred characters of its text if you allowed them. Nothing is stored.
- It encrypts what it read with a key your device generated and gave to no one else, and sends that as the notification. Your device decrypts it; nothing in between can.
- You choose which of the three a notification may show, on the screen that asks for notifications, and you can change it later. Unticking the first lines means the server does not ask your mailbox for them at all. The sender and the subject it reads in any case: your rules and the away message are built on them, and it cannot apply a rule to a message it has not looked at. What you untick is not sent to your device and is not stored anywhere.
- It does not read the rest of the message and does not download attachments.
- It does move and mark messages — but only the ones your own rules name, and only the way you told them to: into a folder, read, starred, or quietly. A snoozed letter is moved out of the inbox and back again at the time you set, and a letter queued to be sent leaves the queue when it goes. Nothing else in the mailbox is touched, and with no rules, no away message and nothing snoozed, the server only reads and never writes.
Delivery runs on the platform’s own channel — Apple’s on iPhone, iPad and Mac, Google’s on Android. There is no other route to a device on either platform. What they carry is the encrypted payload above: both can see that a notification was sent to you, and neither can see who wrote or what about.
What we will not claim: that encryption at rest protects this from us. A service obliged to keep a connection open must be able to read the credentials continuously, so the key sits alongside them. Encryption here protects against a leaked backup or a stolen disk image — a real risk, and a smaller one than the honest description above.
Disconnect the mailbox in the app and the stored access is erased from the server. So does turning notifications off on the notifications screen — the server stops watching the mailbox and forgets the access. Unticking what a notification may show is a different thing: it changes what is sent, not whether the mailbox is watched.
What the server keeps for you
Some things you ask the app to do have to keep working while your phone is off, so the server keeps what it needs for them — and nothing beyond it:
- Rules — the conditions and actions you wrote yourself.
- Away message — the subject and text you wrote, and the addresses it has already answered, so that nobody gets it twice.
- Snoozed letters and letters waiting to be sent — the mailbox, the folder, the message number and the time. The letters themselves stay in your own mailbox; we keep a reminder, not a copy.
Delete a rule or the away message and it is gone from the server. Disconnect the mailbox and all of it goes with the stored access.
Images in messages
Most messages carry images whose real job is to report that you opened them, and when, and from where. Tiho fetches those images through our own server instead of from your device.
- The sender's server sees a request from us. Not your address, not your IP, not the moment you read.
- We keep nothing about who requested what. The proxy holds no log tying an image to a reader.
- Images of one pixel, and images the sender marked hidden, are never fetched at all — by us or by you. They have no purpose other than reporting on you.
Sender logos
A sender's logo is read from the sender's own domain: first a public record published in its DNS, and if there is none, the icon of its website. Either address is the same for every recipient and carries no identifier, so requesting it cannot reveal that you opened a particular message. Both are cached on your device, and both stop entirely when you turn sender logos off in Settings.
Bulk mail
Campaigns are sent through a delivery service you sign up for yourself, with your own key. We never send on your behalf, and your recipient list never reaches us: it stays on your device, and the addresses go to your delivery service alone, at the moment you press send.
One thing does reach us, and it is the unsubscribe link. Every recipient gets their own, carrying a random value and nothing else — no address, no name, no campaign. When someone follows it, we record that value. Your app asks us about its own values and learns which of them unsubscribed. We cannot work out whose address any of them is, because we were never told.
Why this lives with us at all: a person unsubscribes from their own mail program, and there is no other place to hear about it.
Documents
Used offline, the document editor makes no network connections at all. There is nothing to send and nothing to describe here.
If you subscribe to storage, the documents you choose to sync are stored on our servers so they can reach your other machines. The copy on your disk stays canonical. Cancelling stops the syncing and never strands a file.
What we do not do
- No advertising, and no data sold or shared for it.
- No analytics inside the app that report what you read or who writes to you.
- No third-party requests from this website: fonts, images and scripts are served from here.
Requests from authorities
We answer lawful requests we are obliged to answer, and nothing beyond them. What can be handed over is limited by what exists: for a mailbox we do not host, that is the stored access described above and the fact that a device is registered for notifications — not your correspondence, which we do not hold.
Erasing everything
Disconnecting a mailbox in the app erases the stored mail and credentials from that device, and erases the stored access and the notification registration from our servers. Nothing is kept in reserve.
Changes
If this policy changes in a way that affects what we hold, the change is described here with a date rather than replaced silently.
Contact
Questions about any of this: hello@tiho.one.
This text is written in English, and the English wording is the one that governs. If you need help understanding any part of it in your own language, write to hello@tiho.one and a person will explain.